Description
Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()
calls in the Workflow, Form block, and File/Set components that lack the
allowed_classes restriction. The Form block and File/Set sinks were addressed in
9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated
attacker may trigger arbitrary PHP object instantiation if a malicious serialized
payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan
(dizconnect) for independently reporting the original components, and sh4d0byss for
reporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this
vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/
VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
Published: 2026-06-03
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Concrete CMS versions below 9.5.3 are vulnerable to PHP Object Injection because the Workflow, Form block, and File/Set components use unserialize() without restricting allowed_classes. The Form block and File/Set sinks were patched in 9.5.2, and the Workflow component was fixed in 9.5.3. An unauthenticated attacker can trigger arbitrary PHP object instantiation by placing a malicious serialized payload in the CMS database; the flaw, identified as CWE‑502, enables code execution with the privileges of the web application, potentially compromising confidentiality, integrity, and availability of the host system. The CVSS v4.0 score of 8.4 indicates a high‑severity condition with low effort and local access required.

Affected Systems

Concrete CMS installations running any version prior to 9.5.3 are susceptible. The Form block and File/Set components were corrected in 9.5.2, while the Workflow component was addressed in 9.5.3. Users on earlier releases, or on 9.5.2 with active workflows, must verify their version and apply an upgrade.

Risk and Exploitability

The CVSS score of 8.4 highlights a high‑severity condition with low effort to exploit (local access required, low attack complexity, no authentication needed). Based on the description, the likely attack vector requires an attacker to place a crafted payload in the CMS database, thus triggering the vulnerable unserialize() calls that lead to arbitrary PHP object instantiation. The EPSS score of less than 1 % indicates that active exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog, so there are no documented public exploits. Nevertheless, the impact of successful exploitation is the potential for complete code execution on the system.

Generated by OpenCVE AI on September 21, 2026 at 08:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later, which removes the unsafe unserialize() calls and restores allowed_classes restrictions.
  • Enforce allowed_classes in all custom unserialize() usage within the application to limit deserialization to whitelisted classes.
  • Remove or sanitize any database entries that may contain malicious serialized data and implement input validation to reject unexpected object data in forms and workflow components.

Generated by OpenCVE AI on September 21, 2026 at 08:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-52pr-7vmf-2w7x Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components
History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for both independently reporting. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for independently reporting the original components, and sh4d0byss for reporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/ VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
Title Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.

Wed, 03 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Wed, 03 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for both independently reporting. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
Title Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction.
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:04:23.786Z

Reserved: 2026-05-05T20:23:08.863Z

Link: CVE-2026-7888

cve-icon Vulnrichment

Updated: 2026-06-03T19:07:52.022Z

cve-icon NVD

Status : Deferred

Published: 2026-06-03T19:16:38.910

Modified: 2026-09-11T20:18:54.320

Link: CVE-2026-7888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T08:15:11Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data